Security researchers describe SparkKitty, a piece of malware distributed through mobile app stores, that targets cryptocurrency wallet recovery (seed) phrases. According to reports, the malware infects iOS and Android devices after being packaged into legitimate-looking mobile applications available on Apple’s App Store and Google Play. Once installed, SparkKitty reportedly scans photos stored on the infected device to locate images that may contain wallet seed phrases, then extracts that information for theft.

The analyses highlight that the attack focuses on commonly shared or stored wallet recovery information—such as screenshots or pictures—rather than directly intercepting cryptocurrency transactions. Researchers say the malware’s behavior includes identifying relevant content in the photo library and collecting the extracted phrases.

The two outlets summarize findings from a detailed investigation by Check Point, which describes SparkKitty’s distribution and photo-scanning capabilities across both iPhone and Android environments. The reports do not indicate a single affected wallet platform, but they consistently frame the threat as targeting users who store or photograph recovery phrases on their phones.